3913 token Hack

TOTAL LOST $31K
Low Flash Loan Attacks

What happened

Deflationary token 3913 suffers a $31,354 USD loss in a flash loan attack on BNB Smart Chain.

On November 2, 2023, the deflationary token 3913 on BNB Smart Chain was exploited through a flash loan attack. The attacker utilized a loophole in the token's in_transfer function, which was designed to give bonuses to new token holders when a Pancake pair sends tokens to the new user. However, the contract failed to account for a malicious user forcing a Pancake/Uniswap pair to transfer tokens to any address via a skim() call.

The attacker took a flash loan, bought 3913 tokens, and repeatedly transferred these tokens to the pair address while calling skim(), tricking the contract into giving away all available bonuses. As of November 20, 2023, the stolen funds, amounting to $31,354.82 USD, still remain in the scammer's address as BSC-USD.

Attacker address:

https://bscscan.com/address/0xb29F18B8…8D8ae7

Malicious transaction:

https://bscscan.com/tx/0x8163738d…6199ed

Malicious contract:

https://bscscan.com/address/0x783FBEa4…025E83

Case & protocol details

Classification Token
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract 3913

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.